Recent findings have revealed that H96 streaming devices are linked to an extensive ad fraud network, which not only exploits users’ internet connections but also masquerades as mobile phones to generate fraudulent ad clicks. This alarming discovery was made by Pedro Falé, a threat researcher at Bitsight, who uncovered the operation by registering an expired domain previously used for coordinating fake ad clicks. The implications of this fraud extend to online merchants and advertising networks, raising significant concerns for cybersecurity defenders.
Ad Fraud Mechanism
Falé’s investigation into the H96 devices revealed that they were transmitting data while claiming to be various mobile phone models from manufacturers like Samsung and Huawei. This spoofing allows the devices to participate in a fraudulent ad-clicking scheme on AI-generated websites operated by the Fengwo Group, a company based in mainland China.
Operational Insights
The analysis indicated that the H96 devices were either functioning as residential proxies or engaging in ad fraud, but not simultaneously. When a television is connected, the device acts as a proxy; when the TV is off, it shifts to ad fraud activities. This dual functionality highlights the resource-intensive nature of the ad fraud operations.
Revenue Estimates
Bitsight estimates that this ad fraud network generates approximately $50,000 daily, based on telemetry from around 38,000 devices globally. The Fengwo Group’s claims of having over 120,000 “AI digital humans” at their disposal may serve as a marketing tactic to obscure the true nature of their operations.
For more detailed insights, refer to the full report by KrebsOnSecurity.


